Skip to main content
OptiFlow

Security & reliability

How we look after your business’s data

This page describes practices and capabilities as they actually operate in the product — no claims about standards, and no promises we cannot stand behind.

Role-based permissions

Every user works inside the permissions of their role. Actions and information are exposed according to what the job requires — not according to who reached the computer first.

Per-business separation

Each business’s data is managed separately. One business is never exposed to another business’s data.

Clinical masking by role

Clinical details — exams and prescriptions — are masked on the server side from non-clinical roles. Anyone whose work does not require them simply does not receive them.

Audit records

Sensitive actions leave a record: who did what, and when. The record serves the business’s internal control.

Encrypted transport

Access to the system runs over an encrypted connection.

Backups

Data is backed up routinely, and the backups are validated — an unvalidated backup does not count as one.

Health monitoring

System health is monitored, so problems are identified and handled — instead of being discovered through a customer.

Controlled document access

Customer documents are delivered through dedicated, controlled links — not as openly reachable files.

This page describes working practices as implemented in the product. No certification, standard or regulatory approval is claimed, and no certified compliance with any security or privacy standard is claimed.

Responsible disclosure

Found a security issue? We would like to hear about it directly, before any publication, so we can address it.

Report through the contact form on this site — security reports are handled with priority.

Want to see how OptiFlow could fit your business?

We’ll set up a personal demo, learn how you work today, and show the capabilities that matter for your store or clinic.